VYPR

AMD SMM communication buffer

by AMD

CVEs (3)

  • CVE-2022-23820HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.

  • CVE-2024-36311MedFeb 10, 2026
    risk 0.30cvss epss 0.00

    A Time-of-check time-of-use (TOCTOU) race condition in the SMM communications buffer could allow a privileged attacker to bypass input validation and perform an out of bounds read or write, potentially resulting in loss of confidentiality, integrity, or availability.

  • CVE-2024-36310MedFeb 10, 2026
    risk 0.30cvss epss 0.00

    Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds read or write to SMRAM potentially resulting in loss of confidentiality or integrity.